VulnerabilityModified
CVE-2016-2298
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.
CRITICAL 9.8EPSS 25.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 25.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 25.09% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- meteocontrol/web\'log basic 100 · meteocontrol/web\'log light · meteocontrol/web\'log pro · meteocontrol/web\'log pro unlimited
- Source
- ics-cert@hq.dhs.gov
References
- http://seclists.org/fulldisclosure/2016/May/52
- https://ics-cert.us-cert.gov/advisories/ICSA-16-133-01Third Party Advisory, US Government Resource
- http://seclists.org/fulldisclosure/2016/May/52
- https://ics-cert.us-cert.gov/advisories/ICSA-16-133-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.